TechCrunch made the case Sunday that the infrastructure labs use to test whether a model is dangerous has itself become a source of danger — sandboxes built for yesterday’s capability, run faster and at greater scale than the people watching them can keep up with. Five weeks into this publication’s running list of agent-containment failures, it’s less an argument than a pattern with citations. The same week, Zenity Labs demonstrated zero-click hijacks against Claude, Gemini, Comet, Atlas, and Copilot Edge alike at Black Hat — no click, no approval dialog, just an agent reading a web page it shouldn’t have trusted. Different failure mode, same underlying fact: these systems now act in the world faster than anyone can verify they’re doing it safely, in production browsers as much as in the eval environments meant to catch the problem first.
Anthropic, meanwhile, answered a much older question — who pays for all this — with a structure built to keep the exposure off its own books. Theseus, a new venture with Macquarie Asset Management and Singapore’s GIC, will own and finance a fleet of US data centers that Anthropic then leases; Anthropic’s own exposure is essentially capped at covering local electricity-rate increases the buildout causes. It’s a sane instinct at a moment when Bloomberg reports underwriters are getting nervous about AI-linked debt, steering data-center bond sales toward patient buyers like pension funds rather than the broader market. Compute keeps scaling; increasingly, someone else’s balance sheet is absorbing the risk of it.
Physical AI had its own milestone this week, and it belongs to China. AgiBot shipped roughly 8,400 humanoid robots in the first half of 2026 — 44% of the global market, up 562% year on year — edging past longtime leader Unitree, which took 31%. Together the two now account for three-quarters of every humanoid robot shipped on Earth, and both are converting that lead into public capital: Unitree opened IPO subscriptions this week at a $9 billion valuation, with rival lab DeepSeek listed among its strategic investors. The humanoid-robot race and the LLM race are increasingly financed by the same handful of Chinese firms, which makes them less like separate stories than the same story wearing a different chassis.
California didn’t wait for any of this to sort itself out in Washington. Governor Newsom announced the first state-run AI Cyber Defense Program this week — an AI-driven vulnerability-detection unit inside the state’s cybersecurity center, an AI Cybersecurity Officer in every agency, and expanded defenses for local governments and infrastructure operators. It arrives the same week three startups selling defenses specifically for AI agents — Zenity, Obsidian Security, and Oligo — raised a combined $270 million (this edition’s number, below), which is really the private-sector version of the same bet: that the gap between what these systems can now do and what anyone can verify they’re doing safely is wide enough to build a market on, whether the customer is a state government or an enterprise security team.
None of these four stories needed each other to be true. But read together, they describe an industry moving in two directions it hasn’t reconciled: outward, into browsers, robots, and physical infrastructure, faster than its own testing can certify; and inward, into financing structures designed to make sure that if something breaks, it isn’t obviously anyone’s balance sheet that absorbs it. The tests keep failing quietly. The money keeps moving. The robots keep shipping regardless.